L1. Scope & Relationship
This supplement applies to Lens, including customer workspaces, Lens APIs, and customer-deployed Lens Agents. It supplements the CVP Privacy Policy. That policy applies to matters not addressed here; this supplement controls where it is more specific.
L2. Roles
CVP is the controller of information used for Lens account administration, billing, security, support, and CVP's business operations. For assessment data submitted by a Customer or collected through an authorized Customer deployment, the Customer generally acts as controller or business and CVP acts as processor or service provider under the applicable agreement.
Customers and MSPs are responsible for establishing a lawful basis and obtaining any authorization required to assess systems, networks, domains, and assets submitted to Lens.
L3. Lens Data
- Account and access data: name, work email, company, role, memberships, invitations, delegated-access grants, authentication identifiers, and login activity.
- Commercial data: billing contacts, subscription, plan, invoice, tax, transaction, and payment-method metadata processed with Stripe. CVP does not store full payment-card numbers.
- Assessment and Customer Data: authorized targets and related public-facing assets Lens discovers; inventory and topology; hostnames; IP and MAC addresses; device, port, service, DNS, certificate, API, finding, evidence, scan, report, and sanitized configuration data.
- Agent data: Agent identifiers, claim and check-in activity, diagnostic data, and hashed Agent credentials.
- Operational and audit data: request identifiers, source IP, timestamps, actions, affected resources, feature usage, and diagnostic events.
- Communications: invitations, support messages, privacy and security correspondence, and other transactional communications.
L4. How Lens Uses Data
- Provide network, topology, vulnerability, API-exposure, and public attack-surface assessment features.
- Authenticate users and Agents; administer workspaces, roles, delegated access, subscriptions, and entitlements.
- Generate findings, evidence, reports, exports, and security audit history.
- Process billing and send invitations, password-setup messages, grant-expiry notices, and other service communications.
- Operate, troubleshoot, secure, and prevent misuse of Lens.
- Comply with law and improve Lens using aggregated or de-identified information.
L5. Assessment Data Flows
Lens may contact Customer-designated targets and related public-facing assets discovered during an authorized assessment. It may query public certificate, DNS, service-exposure, breach, email-posture, and vulnerability-intelligence sources using a domain, hostname, public IP address, service, or vulnerability identifier. Those services can receive the query, the requesting Lens system's IP address, and ordinary request metadata.
The current sources are listed separately on our Service Providers & External Data Sources page. Customers should not submit targets they are not authorized to assess or upload raw credentials, payment-card data, or unnecessary secrets.
L6. Hosting & Data Location
Lens's primary application and database workloads are hosted in Microsoft Azure's Central US region. Lens web traffic is processed through Cloudflare's global network, and assessment evidence is stored in Cloudflare R2. Stripe, Microsoft, Google, and technical-intelligence providers may process limited information through their own regional or global infrastructure.
Lens is offered commercially on a United States-focused basis at this stage, but CVP does not represent that every network request or service-provider operation remains exclusively within one U.S. region.
L7. Providers
Lens uses Microsoft Azure for application, database, queue, backup, and secrets infrastructure; Cloudflare for DNS, security, web delivery, and evidence storage; Stripe for billing and payments; Microsoft 365 and Graph for transactional email and support correspondence; and Microsoft Entra or Google Workspace when a Customer chooses federated sign-in.
See the current provider list for purposes and data categories.
L8. Retention & Deletion
Lens retains Customer Data according to the applicable plan and customer agreement and for as long as reasonably needed to provide and secure the Service. Billing and business records may be retained longer to satisfy legal, tax, accounting, dispute, and enforcement obligations. Security records may also be retained for investigation and integrity purposes.
Following termination or a verified deletion request, CVP applies its then-current offboarding and deletion process, subject to the customer agreement, available export periods, backup rotation, and documented legal or security holds. Backup copies are allowed to expire through ordinary rotation rather than being altered individually.
L9. Security
Lens uses encryption in transit and provider-managed encryption at rest, Azure Key Vault for application secrets, tenant-scoped application authorization, hashed Agent credentials, and durable records of security-sensitive account and administrative actions. No safeguard can guarantee absolute security.
Report a suspected Lens vulnerability or security incident to [email protected].
L10. Access, Export & Contact
Authorized users may export reports, topology, findings, audit information, and other data where the applicable Lens feature and plan make an export available. Requests concerning personal information or a broader Customer Data export or deletion should be sent to [email protected]. We may verify the requester's identity, role, and authority with the relevant Customer.